2026 CVE Vulnerabilities

52,737 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-29780MEDIUM5.5eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-29778MEDIUM6.5pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed...
CVE-2026-29771MEDIUM6.5Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ...
CVE-2026-29190MEDIUM5.3Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra...
CVE-2026-29076MEDIUM5.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u...
CVE-2026-3664MEDIUM5.5A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum...
CVE-2026-29184MEDIUM6.5Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template c...
CVE-2026-2433MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Ba...
CVE-2026-2420MEDIUM4.4The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a...
CVE-2026-1825MEDIUM6.4The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod...
CVE-2026-1824MEDIUM6.4The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo...
CVE-2026-1823MEDIUM6.4The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco...
CVE-2026-1820MEDIUM6.4The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv...
CVE-2026-1805MEDIUM6.4The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist ...
CVE-2026-1574MEDIUM6.4The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shor...
CVE-2026-1569MEDIUM6.4The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i...
CVE-2026-1087MEDIUM4.3The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-1086MEDIUM4.3The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2026-1085MEDIUM4.3The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-1073MEDIUM4.3The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2026-1071MEDIUM4.4The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-30842MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti...
CVE-2026-30841MEDIUM6.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs...
CVE-2026-30839MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications....
CVE-2026-30830MEDIUM6.1Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now